Backdoor

What is “Backdoor:Win32/NetWireRAT.MK!MTB”?

Malware Removal

The Backdoor:Win32/NetWireRAT.MK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/NetWireRAT.MK!MTB virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

How to determine Backdoor:Win32/NetWireRAT.MK!MTB?


File Info:

crc32: 22BD7B0B
md5: dbd37b8c044a27ec8008c6489231075f
name: DBD37B8C044A27EC8008C6489231075F.mlw
sha1: cc5b97876fe9b09e2e0618a9f1a7c4dc1d78d129
sha256: 5226a12dc7f7b5e28732ad8b5ad6fa9a35eadfbeec122d798cd53c5ef73fe86a
sha512: 2ac7bc5b879ee7088e91120ef9b5b22d58b7be28f59960317524948e78417021cd13ba4701367e701e453cde84e64b29072643b6a183a203c506070a71d6d166
ssdeep: 6144:ZlfjLIs254Cz4FatkOAOqQxM3QLylFzk8x2dQ325Y/XDzQsFv:Z9jLIs25BrxM3+yHY84dQmGzz7F
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) Adobe Inc. 2021
InternalName: Adobe.exe
FileVersion: 10.23.243.1232
CompanyName: Adobe Inc.
ProductName: Adobe Acrobat
ProductVersion: 10.45.3432.5653
FileDescription: Adobe Acrobat
OriginalFilename: Adobe.exe
Translation: 0x0009 0x04b0

Backdoor:Win32/NetWireRAT.MK!MTB also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
LionicTrojan.Win32.NetWiredRC.m!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealBackdoor.NetWiredRC
ALYacBackdoor.RAT.Netwire
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaBackdoor:Win32/NetWiredRC.2bb33a34
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.76fe9b
CyrenW32/Trojan.MDZV-6496
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Backdoor.Win32.NetWiredRC.gen
BitDefenderGen:Variant.Johnnie.372218
MicroWorld-eScanGen:Variant.Johnnie.372218
TencentWin32.Backdoor.Netwiredrc.Wvkl
Ad-AwareGen:Variant.Johnnie.372218
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34058.wu0@auw5GCdi
TrendMicroTrojanSpy.Win32.TRICKBOT.SMC
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeGeneric.mg.dbd37b8c044a27ec
EmsisoftGen:Variant.Johnnie.372218 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/AD.NetWiredRc.nbefz
KingsoftWin32.Heur.KVM007.a.(kcloud)
MicrosoftBackdoor:Win32/NetWireRAT.MK!MTB
GDataGen:Variant.Johnnie.372218
AhnLab-V3Trojan/Win.TRICKBOT.C4567194
McAfeeRDN/Generic BackDoor
MAXmalware (ai score=81)
VBA32BScope.Backdoor.NetWiredRC
MalwarebytesMalware.AI.334160484
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojanSpy.Win32.TRICKBOT.SMC
RisingTrojan.Generic@ML.85 (RDML:WNrzfhmSOTMqfwuBWSaiAA)
IkarusTrojan.NetWiredRC
MaxSecureTrojan.Malware.74150817.susgen
FortinetW32/TrojanSpy_Win32_TRICKBOT.SMC
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.NetWire.HgIASZYA

How to remove Backdoor:Win32/NetWireRAT.MK!MTB?

Backdoor:Win32/NetWireRAT.MK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment